Agentic AI and Ethics: What Social Workers Need to Know Now
Agentic AI is becoming an important development in artificial intelligence because it changes what technology can do on our behalf. Many social workers are becoming familiar with generative AI tools that draft text, summarize information, or respond to questions. Agentic systems can go further: they can plan steps, use connected tools, and carry out tasks with varying degrees of human involvement.
For social workers, this shift raises a fundamental ethical concern. When technology begins to act on our behalf, questions of responsibility, judgment, and accountability become more complicated. A generated response can be reviewed before it is used. An automated action may already have changed a record, sent a message, or shared information before a social worker sees it.
The conversation therefore needs to move beyond whether AI produces accurate answers. We also need to ask what it is permitted to do, whose information it can access, and what happens when its actions affect someone’s care, safety, or access to services.
This post offers a practical, ethics-grounded explanation of agentic AI and why it matters for social work practice, supervision, education, and professional responsibility. The examples below are hypothetical scenarios intended to help social workers examine potential uses and risks.
What Agentic AI Actually Is
Agentic AI refers to systems designed to operate with a degree of autonomy in pursuit of a goal. Rather than requiring a separate instruction for every step, an agent may determine a sequence of tasks, use tools to carry them out, and adjust its next steps based on the results. Its capabilities depend on its design, the tools it can access, and the permissions people give it.
For example, a social worker might ask a conventional AI tool to draft a checklist for organizing a community workshop. An agentic system connected to other applications could potentially create the checklist, identify available meeting times, draft invitations, and update a project tracker. Whether it can actually send invitations or change a calendar should depend on explicit permissions.
That distinction matters. Permission to generate a suggestion is different from permission to carry out an action.
The word “agentic” also does not mean that a system possesses human understanding, ethical awareness, or professional competence. A system may successfully complete a sequence of tasks while misunderstanding the context in which those tasks occur. Completing a workflow does not establish that the workflow was appropriate for a particular client or community.
For social workers, understanding agentic AI begins with practical questions: What goal has the system been given? What information can it access? What actions can it take? At what point must it stop and ask a person?
Why Agentic AI Is Different From Other AI Tools
Most conversations about AI in social work focus on tools that support documentation, summarization, brainstorming, or administrative work. These uses already require careful attention to accuracy, confidentiality, and professional judgment. Agentic AI adds another layer because an error can move beyond a draft and become an action.
Consider a tool that summarizes a client’s service needs incorrectly. If a social worker reviews the summary, the mistake may be corrected before it enters the record. Now imagine a connected system that uses that summary to select a referral, complete a form, and send information to an outside organization. One misunderstanding could affect several steps.
This creates the possibility of cascading errors. Each subsequent action may appear reasonable because it relies on an earlier output that was never verified.
The boundary between conventional generative AI and agentic AI is not always clear. Some products combine drafting, recommendations, and automated actions within the same interface. Social workers therefore need to examine what a particular feature actually does rather than relying on a product’s label.
Social work ethics emphasize informed consent, competence, self-determination, and confidentiality. These responsibilities continue to apply when technology supports service delivery. The NASW Code of Ethics specifically addresses technology-related consent and competence; it does not make those obligations disappear when a system performs a task for us.
Where Social Workers May Encounter AI Agents
Agentic AI may be introduced as a response to real pressures: burnout, staffing shortages, administrative overload, and growing caseloads. These conditions make automation appealing. A system that reduces repetitive work could help create more time for relationship-building, advocacy, and direct support.
However, the purpose of automation needs careful examination. Is the organization trying to improve care, reduce administrative burden, increase caseloads, or reduce staffing? These goals can produce very different expectations and outcomes.
The ethical significance depends on the action. Organizing a deadline is different from deciding that a family has failed to comply. Preparing a referral draft is different from sharing a client’s information. Flagging a missing document is different from recommending that services be discontinued.
Even administrative tasks can have serious consequences. An automated reminder sent to an unsafe phone number could expose a person’s involvement with a domestic violence program. A scheduling system that repeatedly offers inaccessible appointment times could create barriers for a client with a disability or unpredictable work schedule.
Every automated workflow reflects choices about whose needs matter, what counts as success, and which risks an organization is willing to accept.
Ethical Practices for Social Work and Agentic AI
Agentic AI requires explicit limits. A broad instruction such as “support case management” leaves too much room for interpretation when a system can access records or communicate with others.
The following are boundaries I recommend for social work practice. They are an ethical application of professional responsibilities, rather than a claim that existing codes contain these exact agent-specific rules.
Agentic AI should not be permitted to:
Independently make or finalize consequential professional decisions, including diagnoses, treatment changes, safety determinations, placement recommendations, or decisions affecting access to services.
Access, use, or disclose client information beyond an explicitly authorized purpose, with appropriate informed consent and any applicable legal basis.
Replace supervision or professional judgment, including the contextual reasoning necessary to assess conflicting information.
Take consequential actions without an identified human decision-maker, clear approval requirements, and an escalation process.
Conceal its role or obscure responsibility, including presenting automated communication as a personally reviewed message when it has not been reviewed.
Consent deserves particular attention. A general agreement to receive services should not be assumed to explain every possible use of an AI system. Clients need understandable information about what the technology does, what information it uses, and what choices they have. Consent also does not, by itself, make an unsuitable or insecure system appropriate.
Where disclosure without consent is legally required or otherwise ethically justified, that exception should be assessed and documented by an authorized professional. An AI agent should not independently decide that an exception applies.
Boundaries need to be built into permissions and workflows. Writing “do not share confidential information” in a prompt provides limited protection if the system still has unrestricted access to records and the ability to send them.
Need for Human Oversight
Many organizations claim that human oversight will address ethical concerns. That phrase needs to describe a real process.
A social worker cannot meaningfully oversee a system if they cannot see what it has done, lack time to review its work, or have no authority to stop it. Oversight becomes especially weak when staff are expected to approve large volumes of outputs quickly.
A human approval button is useful only when the person approving has the information, competence, time, and authority to make a considered decision.
In practice, meaningful oversight should include:
Defined permissions: Specify which tasks the agent may complete and which require approval.
Review before consequential action: Require appropriate review before information is disclosed, records are materially changed, or actions affect care and services.
Visible activity records: Maintain a usable record of information accessed, actions attempted, approvals obtained, and errors encountered.
Stop and escalation procedures: Identify who can pause the system and what it must do when information is missing, contradictory, or outside its scope.
Assigned responsibilities: Clarify the roles of practitioners, supervisors, organizational leaders, technology staff, and vendors.
Ongoing evaluation: Reassess the system when its features, permissions, or intended uses change.
For example, an agent may prepare a referral packet for review while being unable to transmit it. A social worker can verify the destination, confirm the client’s preferences, and check that the packet includes only necessary information before authorizing release.
Oversight must also address workload. If automation produces more material than staff can responsibly review, an organization has created an oversight problem. Professional accountability requires institutional support; it should not become a way to place all responsibility on individual practitioners while denying them control over the system.
Invisible Risk of Harm
One of the most serious concerns about agentic AI is that harm can become harder to see. Automated systems may make small, repeated choices that gradually shape a person’s experience of services.
Imagine an outreach system that prioritizes clients who respond quickly to electronic messages. Over time, it might give less attention to people with limited internet access, language barriers, unstable housing, or concerns about digital privacy. A pattern that looks efficient could reinforce existing inequities.
Or consider a system that carries an inaccurate description from one document into another. A tentative observation may begin to look like an established fact because it appears repeatedly. Future staff may rely on that description without knowing where it originated.
In social work, harm also appears through relationships. A client may feel watched, misunderstood, or excluded from decisions about their own life. Automated communication may undermine trust if someone believes they are interacting directly with a social worker and later learns that messages were generated and sent without review.
There are also security questions when an agent reads outside material. For example, a webpage or document could contain instructions intended to redirect the system’s behavior. Organizations should examine how the system distinguishes information it should read from instructions it is authorized to follow.
Evaluation must therefore go beyond speed, task completion, or the number of cases processed. It should ask whether clients experience greater access, dignity, safety, and control—and whether some groups experience more errors or barriers than others.
Approaches for Social Work Practice and Agentic AI
Social workers do not need to become software engineers to engage ethically with agentic AI. We do need enough understanding to evaluate a proposed use and recognize when technical consultation is necessary.
A grounded approach begins with the practice problem. What task needs support? Why is an agent needed? Could a simpler tool accomplish the goal with fewer permissions and less exposure of sensitive information?
From there, social workers can ask:
What can the system read, change, send, or delete?
What happens if its information is inaccurate or incomplete?
Which actions require professional approval?
How will clients learn about its role and express their preferences?
Who responds when it makes an error?
How will the organization detect unequal outcomes?
What would cause us to pause or discontinue its use?
Start with a narrow task and test it using fictional information before introducing it into practice. Testing should include difficult situations, such as conflicting records, inaccessible resources, ambiguous instructions, and missing information. A demonstration in which everything goes smoothly tells us little about how a system behaves when practice becomes complicated.
Supervision is an important place to examine these questions. Supervisors and supervisees can establish written expectations about approved uses, restricted actions, documentation, and consultation. The discussion should include how AI use affects learning: Is the supervisee developing their reasoning, or accepting the system’s plan without being able to explain it?
Social work education can similarly give students opportunities to evaluate an agent’s proposed steps, identify missing context, and decide when it should stop. The learning goal should include the ability to justify a decision and recognize uncertainty.
A grounded approach also makes room for refusal. If an organization cannot explain the system’s permissions, provide adequate safeguards, or support meaningful review, postponing adoption may be the responsible decision.
Moving Forward With Intention
The possibility of delegating action to AI makes governance a practical concern for social work. Boundaries need to be established before a workflow becomes routine and difficult to change.
Social workers bring essential knowledge to these decisions. We understand that a missed appointment can reflect transportation barriers, that apparent disengagement may be connected to trauma or distrust, and that a complete record can still leave out a person’s strengths and priorities.
That understanding needs to influence how systems are designed and evaluated. Social workers should participate in procurement, pilot planning, policy development, and decisions about acceptable uses. Clients and communities should also have opportunities to shape tools that affect their services.
Agentic AI may offer useful support when tasks are carefully defined and safeguards are meaningful. It also requires us to be precise about what we are willing to delegate.
Social work has always held complexity, context, and human dignity at its center. Those commitments need to appear in the everyday details of an AI workflow: its permissions, approval requirements, consent conversations, supervision practices, and response to mistakes.
Responsible adoption should preserve time for relational work and strengthen professional judgment. It should also allow practitioners and clients to question an automated action, correct an error, and reach a person who has the authority to respond.
As these systems develop, we need to keep asking: Who authorized this action? Whose goals does it serve? What information informed it? Who can challenge it? And who will take responsibility for repairing harm?
The content in this blog was created with the assistance of Artificial Intelligence (AI) and reviewed and edited by Dr. Marina Badillo-Diaz to ensure accuracy, relevance, and integrity. Dr. Badillo-Diaz's expertise and insightful oversight have been incorporated to ensure the content in this blog meets the standards of professional social work practice.